Live data from Hacker News

1Password for Linux beta

blog.1password.com

31–40 of 254 posts

Re: 1Password for Linux beta

#31

Unpopular opinion: using a password manager as a service is as bad as password reuse: all your passwords behind a single password.

Honestly, I think your opinion is unpopular because it demonstrates a serious lack of understanding or thought. If you re-use the same password for all sites, it takes just one sketchy site being compromised for all of your other sites to become compromised. In the case of a password manager, the manager itself is the one that needs to be compromised, and you have more reason to trust them to avoid being compromised…

Your mistake is assuming I had not thought of that. I have, and my position remains the same.

Re: 1Password for Linux beta

#32
post #27
post #19

Does anyone know if this supports standalone licenses, or is it strictly subscription only?

It seems to be subscription only, just like the Windows and macOS versions. EDIT: I was wrong about 1Password 7 for Windows and macOS, see further replies.

Neither the Windows or macOS versions are subscription-only but they have hidden the standalone license option carefully… See e.g. https://1password.community/discussion/107609/is-1password-7... for some first-hand informaton.

Re: 1Password for Linux beta

#33
post #7

Oh good it's another Electron app and since there are only about 50 random dependencies mentioned in the package.json maintained by about 25 random people, exfiltration of all your passwords is only one of those being compromised away at any given point. And that is just the direct dependencies, I don't even want to look at the tree of it all. If you trust 1password with your passwords, really you are also trusting w…

> exfiltration of all your passwords is only one of those being compromised away at any given point

No, that's absolutely not true.

Those dependencies will not automatically update in your local app. The 1password developers should be auditing all updates to those dependencies too, and if you trust the 1Password developers to be competent, then you don't have to trust 25 random developers.

Furthermore, this isn't unique to electron apps. If they wrote this in c++, you'd still have to trust 1password devs to audit a dozen libraries they'd vendor in.

Re: 1Password for Linux beta

#34

I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.

Agreed. I have been using Bitwarden for over 3 years now, paid premium user as well. No big issues, the odd bug a few times but all fixed promptly and didn't impact my ability to access my data.

While the Bitwarden apps are not as "pretty" as 1Password's I find them a little simpler to use. Obviously UI design is highly subjective though so your thoughts may be very different :)

Anyway yes I highly recommend Bitwarden. Kyle and the team have built and continue to run a top class product that costs 1/3 the price of 1Password.

Edit: To clarify I use Bitwarden solely for personal use. I cannot fairly compare Bitwarden and 1Password for multiuser/shared vault use.

Re: 1Password for Linux beta

#36
Uses Electron. What a shitshow.

Edit: I checked: neither the macOS nor Windows version uses it. So it's not even that they think Electron is acceptable for high-quality desktop apps. They just don't consider Linux important enough to make a high-quality app for it.

Re: 1Password for Linux beta

#37
post #27
post #19

Does anyone know if this supports standalone licenses, or is it strictly subscription only?

It seems to be subscription only, just like the Windows and macOS versions. EDIT: I was wrong about 1Password 7 for Windows and macOS, see further replies.

The 1Password macOS app is not subscription-only; the standalone purchase is just fairly well hidden because it's not the recommended path: https://support.1password.com/upgrade-mac/

This topic inevitably comes up on every HN 1Password thread.

Re: 1Password for Linux beta

#38
post #28

Earlier quoted context omitted.

I'm confused how the self hosting works. Doesn't it force you to give them an email address? Why is that necessary when self-hosting?

https://bitwarden.com/download/ Download does not ask for email

I'm talking about the program, not their website. It makes you enter an email before you can do anything. Says "Log in or create new account to access your vault", with a "Create account" button that asks for an email.

Re: 1Password for Linux beta

#40
post #28

Earlier quoted context omitted.

https://bitwarden.com/download/ Download does not ask for email

I'm talking about the program, not their website. It makes you enter an email before you can do anything. Says "Log in or create new account to access your vault", with a "Create account" button that asks for an email.

Click the settings "cog" and enter your self-hosted address. Of course you need to have setup your own self-hosted instance first :)
Post reply on HN